Re: Upgraded from 3.2.1 to 3.5 - macros broke?

"Jon Adcock" <[email protected]> Wed, 04 Sep 2013 13:52:46 -0400
Newsgroups gmane.network.nagios.user
Message-ID <[email protected]>
This is a MIME message. If you are reading this text, you may want to 
consider changing to a mail reader or gateway that understands how to 
properly handle MIME multipart messages.

--=__Part1023687E.0__=
Content-Type: multipart/alternative; boundary="=__Part1023687E.1__="

--=__Part1023687E.1__=
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: 8bit

Jason,
 
  Looking at your notify-by-email definition, there are a lot of escape
sequences ( \" ).  I think that's what's messing you up.  My
notify-service-by-email definition is shown below.  Start with that and
tweak it to your taste.
# 'notify-service-by-email' command definition
define command{
	    command_name    notify-service-by-email
	    command_line    /usr/bin/printf "%b" "\nDate/Time:
$LONGDATETIME$\n\nService: $SERVICEDESC$\n\nService check res
ults: $SERVICEOUTPUT$\n\nHost: $HOSTALIAS$\nAddress:
$HOSTADDRESS$\nState: $SERVICESTATE$\n\n***** Nagios *****\n\nNotif
ication Type: $NOTIFICATIONTYPE$\n\nAdditional Info:\n" | /usr/bin/mail
-s "** $NOTIFICATIONTYPE$ Service Alert: $HOSTAL
IAS$/$SERVICEDESC$ is $SERVICESTATE$ **" $CONTACTEMAIL$
	    }
 
Jon




Jon Adcock
Network Systems Administrator
Leon County MIS
301 S. Monroe St.
Tallahassee, FL  32301
Office:  (850) 606-5518
http://www.leoncountyfl.gov
"People Focused.  Performance Driven."
 
 
Please note that under Florida's Public Records laws, most written
communications 
to or from county staff or officials regarding county business are
public records 
available to the public and media upon request.  Your e-mail
communications may 
therefore be subject to public disclosure.



>>> On 9/4/2013 at 1:11 PM, Jason Gauthier <[email protected]>
wrote:


To follow up on my own email. It looks like this is not just the
upgrade. I moved my 3.2.1 binary back in, and it still happens.
 
And I’ve found that it’s not limited to the notification commands:
 
[1378314473] SERVICE ALERT: Server86;Server86 -
Ping;UNKNOWN;SOFT;1;check_ping: Invalid hostname/address - 19216874204
[1378314493] SERVICE ALERT: Server86;Server86 - SAP;CRITICAL;SOFT;1;TCP
CRITICAL - Invalid hostname, address or socket: 19216874204
[1378314503] HOST ALERT: Server86;DOWN;SOFT;1;check_ping: Invalid
hostname/address - 19216874204
[1378314533] SERVICE ALERT: Server86;Server86 -
Ping;UNKNOWN;HARD;2;check_ping: Invalid hostname/address - 19216874204
[1378314543] HOST ALERT: Server86;DOWN;SOFT;2;check_ping: Invalid
hostname/address - 19216874204
[1378314553] SERVICE ALERT: Server86;Server86 - SAP;CRITICAL;HARD;2;TCP
CRITICAL - Invalid hostname, address or socket: 19216874204
[1378314553] SERVICE ALERT: Server86;Server86 -
Load;WARNING;HARD;10;85% CPU load.
[1378314563] HOST ALERT: Server86;DOWN;SOFT;3;check_ping: Invalid
hostname/address - 19216874204
[1378314573] HOST ALERT: Server86;DOWN;SOFT;4;check_ping: Invalid
hostname/address – 19216874204
 
(the periods are removed from the IPs)
I really have no idea what caused this, but I am reviewing my config
and changes I made while testing splunk, and opsgenie integration.
 
 

From: Jason Gauthier 
Sent: Wednesday, September 04, 2013 10:28 AM
To: '[email protected]'
Subject: Upgraded from 3.2.1 to 3.5 - macros broke?

 
Greetings,
 
It seems during a recent upgrade, my notifications broke!  Well, I did
digging and found notification themselves are working, but the macro
variables are completely botched.
 
I took “notify-by-email”, and changed it to this:
/usr/bin/printf "\"%b\" \"Notification Type: $NOTIFICATIONTYPE$
($SERVICEACKAUTHOR$)\n\nService: $SERVICEDESC$\nHost:
$HOSTNAME$\nAddress: $HOSTADDRESS$\nState: $SERVICESTATE$\n\nDate/Time:
$LONGDATETIME$\n\nAdditional Info:\n\n$SERVICEOUTPUT$\n\nComment:
$SERVICEACKCOMMENT$\" | /bin/mail -s \"** $NOTIFICATIONTYPE$ alert -
$HOSTNAME$/$SERVICEDESC$ is $SERVICESTATE$ **\" $CONTACTEMAIL$" >>
/tmp/nagiosnotify.log
 
So, it will write the contents to a file instead of just directly piped
to mail.  Here is what I see:
 
"Notification Type: RECOVERY ($)
 
Service: $
Host: v-ww7b2
Address: 19216876178
State: $
 
Date/Time: W Sp 4 10:18:11 EDT 2013
 
Additional Info:
 
$
 
Comment: $" | /bin/mail -s "** RECOVERY alert - v-ww7b2/$ is $ **" bv
 
 
It seems like all of the variable are wrong. For instance, the host is
v-windows7lab2. 
The email address starts with “bv”, but it ends with a whole lot more!
 
I’m not sure what would be causing this, and would appreciate any
input.
 
Thanks!
 

--=__Part1023687E.1__=
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
Content-Description: HTML

<HTML xmlns=3D"http://www.w3.org/TR/REC-html40" xmlns:v =3D "urn:schemas-mi=
crosoft-com:vml" xmlns:o =3D "urn:schemas-microsoft-com:office:office" =
xmlns:w =3D "urn:schemas-microsoft-com:office:word" xmlns:m =3D "http://sch=
emas.microsoft.com/office/2004/12/omml"><HEAD>
<META content=3D"text/html; charset=3Dutf-8" http-equiv=3DContent-Type>
<META name=3DGENERATOR content=3D"MSHTML 8.00.7601.18210">
<STYLE><!--
/* Font Definitions */
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:11.0pt;
	font-family:"Calibri","sans-serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
span.EmailStyle17
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:windowtext;}
span.EmailStyle18
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></STYLE>
</HEAD>
<BODY style=3D"MARGIN: 4px 4px 1px; FONT: 10pt Segoe UI" lang=3DEN-US =
link=3Dblue vLink=3Dpurple>
<DIV>Jason,</DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp; Looking at your notify-by-email definition, there are a lot of =
escape sequences ( \" ).&nbsp; I think that's what's messing you up.&nbsp; =
My notify-service-by-email definition is shown below.&nbsp; Start with =
that and tweak it to your taste.</DIV>
<DIV># 'notify-service-by-email' command definition<BR>define command{<BR>&=
nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; command_name&nbsp;&nbsp;&nbsp; =
notify-service-by-email<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; =
command_line&nbsp;&nbsp;&nbsp; /usr/bin/printf "%b" "\nDate/Time: =
$LONGDATETIME$\n\nService: $SERVICEDESC$\n\nService check res<BR>ults: =
$SERVICEOUTPUT$\n\nHost: $HOSTALIAS$\nAddress: $HOSTADDRESS$\nState: =
$SERVICESTATE$\n\n***** Nagios *****\n\nNotif<BR>ication Type: $NOTIFICATIO=
NTYPE$\n\nAdditional Info:\n" | /usr/bin/mail -s "** $NOTIFICATIONTYPE$ =
Service Alert: $HOSTAL<BR>IAS$/$SERVICEDESC$ is $SERVICESTATE$ **" =
$CONTACTEMAIL$<BR>&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; }</DIV>
<DIV>&nbsp;</DIV>
<DIV>Jon<BR><SPAN style=3D"WORD-WRAP: normal; FONT-SIZE: 10pt; FONT-WEIGHT:=
 normal">
<DIV><BR></DIV>
<DIV>
<DIV><EM><STRONG></STRONG></EM></DIV>
<DIV><EM><STRONG>
<DIV><EM><STRONG>Jon Adcock</STRONG></EM></DIV>
<DIV></STRONG></EM><FONT size=3D1 face=3DTahoma>Network Systems Administrat=
or</FONT></DIV></DIV>
<DIV><FONT size=3D1 face=3DTahoma>Leon County MIS<BR>301 S. Monroe =
St.<BR>Tallahassee, FL&nbsp; 32301<BR>Office:&nbsp; (850) 606-5518</FONT></=
DIV>
<DIV><A href=3D"http://www.leoncountyfl.gov/">http://www.leoncountyfl.gov</=
A></DIV>
<DIV>"People Focused.&nbsp; Performance Driven."</DIV>
<DIV>&nbsp;</DIV>
<DIV>&nbsp;</DIV>
<DIV><EM><FONT size=3D1>Please note that under Florida's Public Records =
laws, most written communications <BR>to or from county staff or officials =
regarding county business are public records <BR>available to the public =
and media upon request.&nbsp; Your e-mail communications may <BR>therefore =
be subject to public disclosure.<BR></FONT></EM></DIV></DIV></SPAN><BR><BR>=
&gt;&gt;&gt; On 9/4/2013 at 1:11 PM, Jason Gauthier &lt;[email protected]=
m&gt; wrote:<BR></DIV>
<TABLE style=3D"MARGIN: 0px 0px 0px 15px; FONT-SIZE: 1em" border=3D0 =
bgColor=3D#f3f3f3>
<TBODY>
<TR>
<TD>
<DIV style=3D"BORDER-LEFT: #050505 1px solid; PADDING-LEFT: 7px">
<DIV class=3DWordSection1>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">To follow up on my own =
email. It looks like this is not just the upgrade. I moved my 3.2.1 binary =
back in, and it still happens.<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d"><o:p>&nbsp;</o:p></SPAN=
></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">And I=E2=80=99ve found =
that it=E2=80=99s not limited to the notification commands:<o:p></o:p></SPA=
N></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d"><o:p>&nbsp;</o:p></SPAN=
></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">[1378314473] SERVICE =
ALERT: Server86;Server86 - Ping;UNKNOWN;SOFT;1;check_ping: Invalid =
hostname/address - 19216874204<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">[1378314493] SERVICE =
ALERT: Server86;Server86 - SAP;CRITICAL;SOFT;1;TCP CRITICAL - Invalid =
hostname, address or socket: 19216874204<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">[1378314503] HOST =
ALERT: Server86;DOWN;SOFT;1;check_ping: Invalid hostname/address - =
19216874204<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">[1378314533] SERVICE =
ALERT: Server86;Server86 - Ping;UNKNOWN;HARD;2;check_ping: Invalid =
hostname/address - 19216874204<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">[1378314543] HOST =
ALERT: Server86;DOWN;SOFT;2;check_ping: Invalid hostname/address - =
19216874204<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">[1378314553] SERVICE =
ALERT: Server86;Server86 - SAP;CRITICAL;HARD;2;TCP CRITICAL - Invalid =
hostname, address or socket: 19216874204<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">[1378314553] SERVICE =
ALERT: Server86;Server86 - Load;WARNING;HARD;10;85% CPU load.<o:p></o:p></S=
PAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">[1378314563] HOST =
ALERT: Server86;DOWN;SOFT;3;check_ping: Invalid hostname/address - =
19216874204<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">[1378314573] HOST =
ALERT: Server86;DOWN;SOFT;4;check_ping: Invalid hostname/address =E2=80=93 =
19216874204<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d"><o:p>&nbsp;</o:p></SPAN=
></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">(the periods are =
removed from the IPs)<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d">I really have no idea =
what caused this, but I am reviewing my config and changes I made while =
testing splunk, and opsgenie integration.<o:p></o:p></SPAN></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d"><o:p>&nbsp;</o:p></SPAN=
></P>
<P class=3DMsoNormal><SPAN style=3D"COLOR: #1f497d"><o:p>&nbsp;</o:p></SPAN=
></P>
<DIV>
<DIV style=3D"BORDER-BOTTOM: medium none; BORDER-LEFT: medium none; =
PADDING-BOTTOM: 0in; PADDING-LEFT: 0in; PADDING-RIGHT: 0in; BORDER-TOP: =
#b5c4df 1pt solid; BORDER-RIGHT: medium none; PADDING-TOP: 3pt">
<P class=3DMsoNormal><B><SPAN style=3D"FONT-FAMILY: 'Tahoma','sans-serif'; =
FONT-SIZE: 10pt">From:</SPAN></B><SPAN style=3D"FONT-FAMILY: 'Tahoma','sans=
-serif'; FONT-SIZE: 10pt"> Jason Gauthier <BR><B>Sent:</B> Wednesday, =
September 04, 2013 10:28 AM<BR><B>To:</B> '[email protected]=
et'<BR><B>Subject:</B> Upgraded from 3.2.1 to 3.5 - macros broke?<o:p></o:p=
></SPAN></P></DIV></DIV>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>Greetings,<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>It seems during a recent upgrade, my notifications =
broke!&nbsp; Well, I did digging and found notification themselves are =
working, but the macro variables are completely botched.<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>I took =E2=80=9Cnotify-by-email=E2=80=9D, and changed =
it to this:<o:p></o:p></P>
<P class=3DMsoNormal>/usr/bin/printf "\"%b\" \"Notification Type: =
$NOTIFICATIONTYPE$ ($SERVICEACKAUTHOR$)\n\nService: $SERVICEDESC$\nHost: =
$HOSTNAME$\nAddress: $HOSTADDRESS$\nState: $SERVICESTATE$\n\nDate/Time: =
$LONGDATETIME$\n\nAdditional Info:\n\n$SERVICEOUTPUT$\n\nComment: =
$SERVICEACKCOMMENT$\" | /bin/mail -s \"** $NOTIFICATIONTYPE$ alert - =
$HOSTNAME$/$SERVICEDESC$ is $SERVICESTATE$ **\" $CONTACTEMAIL$" &gt;&gt; =
/tmp/nagiosnotify.log<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>So, it will write the contents to a file instead of =
just directly piped to mail.&nbsp; Here is what I see:<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>"Notification Type: RECOVERY ($)<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>Service: $<o:p></o:p></P>
<P class=3DMsoNormal>Host: v-ww7b2<o:p></o:p></P>
<P class=3DMsoNormal>Address: 19216876178<o:p></o:p></P>
<P class=3DMsoNormal>State: $<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>Date/Time: W Sp 4 10:18:11 EDT 2013<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>Additional Info:<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>$<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>Comment: $" | /bin/mail -s "** RECOVERY alert - =
v-ww7b2/$ is $ **" bv<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>It seems like all of the variable are wrong. For =
instance, the host is v-windows7lab2. <o:p></o:p></P>
<P class=3DMsoNormal>The email address starts with =E2=80=9Cbv=E2=80=9D, =
but it ends with a whole lot more!<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>I=E2=80=99m not sure what would be causing this, and =
would appreciate any input.<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P>
<P class=3DMsoNormal>Thanks!<o:p></o:p></P>
<P class=3DMsoNormal><o:p>&nbsp;</o:p></P></DIV></DIV></TD></TR></TBODY></T=
ABLE></BODY></HTML>

--=__Part1023687E.1__=--

--=__Part1023687E.0__=
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

------------------------------------------------------------------------------
Learn the latest--Visual Studio 2012, SharePoint 2013, SQL 2012, more!
Discover the easy way to master current and previous Microsoft technologies
and advance your career. Get an incredible 1,500+ hours of step-by-step
tutorial videos with LearnDevNow. Subscribe today and save!
http://pubads.g.doubleclick.net/gampad/clk?id=58040911&iu=/4140/ostg.clktrk
--=__Part1023687E.0__=
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Nagios-users mailing list
[email protected]
https://lists.sourceforge.net/lists/listinfo/nagios-users
::: Please include Nagios version, plugin version (-v) and OS when reporting any issue. 
::: Messages without supporting info will risk being sent to /dev/null
--=__Part1023687E.0__=--